Skip to main content

Vendor archive

autodesk CVEs

Beta · best-effort

364 CVEs tagged to vendor autodesk19 Critical, 323 High, 21 Medium, 1 Low, 0 Unrated.

CVE-2023-41146

Published Nov 22, 2023

Autodesk Customer Support Portal allows cases created by users under an account to see cases created by other users on the same account.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-41145

Published Nov 22, 2023

Autodesk users who no longer have an active license for an account can still access cases for that account.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-29069

Published Nov 22, 2023

A maliciously crafted DLL file can be forced to install onto a non-default location, and attacker can overwrite parts of the product with malicious DLLs. These files may then have…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-25001

Published Jun 27, 2023

A maliciously crafted SKP file in Autodesk Navisworks 2023 and 2022 be used to trigger use-after-free vulnerability. Exploitation of this vulnerability may lead to code execution.

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-27908

Published Jun 23, 2023

A maliciously crafted DLL file can be forced to write beyond allocated boundaries in the Autodesk installer when parsing the DLL files and could lead to a Privilege Escalation vul…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-25009

Published May 12, 2023

A malicious actor may convince a user to open a malicious USD file that may trigger an out-of-bounds write vulnerability which could result in code execution.

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-25008

Published May 12, 2023

A malicious actor may convince a user to open a malicious USD file that may trigger an out-of-bounds read vulnerability which could result in code execution.

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-25007

Published May 12, 2023

A malicious actor may convince a user to open a malicious USD file that may trigger an uninitialized pointer which could result in code execution.

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-25006

Published May 12, 2023

A malicious actor may convince a user to open a malicious USD file that may trigger a use-after-free vulnerability which could result in code execution.

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-25005

Published May 12, 2023

A maliciously crafted DLL file can be forced to read beyond allocated boundaries in Autodesk InfraWorks 2023, and 2021 when parsing the DLL files could lead to a resource injectio…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-27909

Published Apr 17, 2023

An Out-Of-Bounds Write Vulnerability in Autodesk® FBX® SDK version 2020 or prior may lead to code execution through maliciously crafted FBX files or information disclosure.

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-27907

Published Apr 17, 2023

A malicious actor may convince a victim to open a malicious USD file that may trigger an out-of-bounds write vulnerability which may result in code execution.

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-27906

Published Apr 17, 2023

A malicious actor may convince a victim to open a malicious USD file that may trigger an out-of-bounds read vulnerability which may result in code execution.

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-25010

Published Apr 17, 2023

A malicious actor may convince a victim to open a malicious USD file that may trigger an uninitialized variable which may result in code execution.

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-29067

Published Apr 14, 2023

A maliciously crafted X_B file when parsed through Autodesk® AutoCAD® 2023 could lead to memory corruption vulnerability by write access violation. This vulnerability in conjuncti…

CVSS 7.8 · High

CVE-2023-27915

Published Apr 14, 2023

A maliciously crafted X_B file when parsed through Autodesk® AutoCAD® 2023 could lead to memory corruption vulnerability by read access violation. This vulnerability in conjunctio…

CVSS 7.8 · High

CVE-2023-27914

Published Apr 14, 2023

A maliciously crafted X_B file when parsed through Autodesk® AutoCAD® 2023 can be used to write beyond the allocated buffer causing a Stack Buffer Overflow. A malicious actor can…

CVSS 7.8 · High

CVE-2023-27913

Published Apr 14, 2023

A maliciously crafted X_B file when parsed through Autodesk® AutoCAD® 2023 can be used to cause an Integer Overflow. A malicious actor can leverage this vulnerability to cause a c…

CVSS 7.8 · High

CVE-2023-27912

Published Apr 14, 2023

A maliciously crafted X_B file when parsed through Autodesk® AutoCAD® 2023 can force an Out-of-Bound Read. A malicious actor can leverage this vulnerability to cause a crash or re…

CVSS 7.8 · High
Showing 201-225 of 364 CVEsPage 9 of 15